Moving personal data out of Europe,
on terms that hold up.
Standard contractual clauses are how most companies send personal data from the EU and UK to the rest of the world. This guide covers the four 2021 SCC modules, what a transfer impact assessment involves, where the EU-US Data Privacy Framework stands in October 2026, and the UK's IDTA and Addendum. Not legal advice.
Last updated Published by TryTrustableNot legal advice
Standard contractual clauses (SCCs) are model contract terms adopted by the European Commission that let a company transfer personal data out of the EEA to a country without an adequacy decision. The current set, adopted on 4 June 2021 in Decision (EU) 2021/914, has four modules for controller and processor combinations. Signing them is not enough on its own: Clause 14 requires both parties to assess whether the destination country's laws and practices let the importer comply, and to document that transfer impact assessment. The UK uses its own IDTA, or an Addendum to the EU SCCs.
What are standard contractual clauses?
The GDPR restricts transfers of personal data to countries outside the EEA (Article 44). A transfer is allowed if the destination has an adequacy decision (Article 45), if appropriate safeguards are in place (Article 46), or, for occasional transfers, under a narrow derogation such as explicit consent (Article 49). Standard contractual clauses are the most used safeguard: Article 46(2)(c) lets parties rely on clauses adopted by the Commission without asking a supervisory authority for approval.
The current EU SCCs were adopted on 4 June 2021 in Commission Implementing Decision (EU) 2021/914. The two older sets were repealed from 27 September 2021, and contracts signed on them stopped providing safeguards after 27 December 2022. If a vendor still sends you 2010 clauses, they are out of date. A separate Decision, (EU) 2021/915, provides optional clauses for controller-processor contracts inside the EEA; those are not transfer tools.
The four SCC modules
The 2021 SCCs are modular. You pick the module that matches each party's role, and you can combine modules in one document when a relationship involves more than one flow.
| Module | Exporter to importer | Typical use |
|---|---|---|
| One | Controller to controller | Sharing customer data with a partner who uses it for its own purposes |
| Two | Controller to processor | An EU company using a non-EU SaaS vendor, support desk or hosting provider |
| Three | Processor to processor | An EU-based SaaS vendor using a non-EU sub-processor for its customers' data |
| Four | Processor to controller | An EU processor returning data to a non-EU customer that is its controller |
One contract can combine modules. Modules Two and Three also cover the Article 28 processor terms.
The clauses that need decisions
The text of the clauses cannot be changed, but several clauses offer options and the annexes must be completed. Annex I describes the parties and the transfer, Annex II the security measures, and Annex III the authorised sub-processors where you choose specific authorisation.
| Clause | What it does | What to decide |
|---|---|---|
| 7 | Optional docking clause: new parties can accede later | Whether to include it (it saves re-papering groups) |
| 8 | Data protection safeguards per module: purpose, transparency, accuracy, security, onward transfers | Annex II security measures, which must be specific, not boilerplate |
| 9 | Sub-processors (Modules Two and Three) | Specific prior authorisation or general authorisation from an agreed list, and the notice period |
| 13 | Which supervisory authority oversees the transfer | Named in Annex I.C |
| 14 | Local laws and practices: the transfer impact assessment | Documented assessment, available to the authority on request |
| 15 | Duties if a public authority asks the importer for the data | Notification, challenge and minimal disclosure |
| 17, 18 | Governing law and courts | An EU Member State that allows third-party beneficiary rights (Module Four can choose another country) |
Clause numbers from the Annex to Decision (EU) 2021/914.
One gap to know about: Article 1 of the Decision covers importers whose processing is not subject to the GDPR. Where the importer is already directly subject to the GDPR under Article 3(2), the Commission has said it is developing an additional set of SCCs for that case. As of October 2026 its SCC page still describes that work as in progress, so take advice on how to paper those transfers.
What is a transfer impact assessment?
A transfer impact assessment (TIA) is the analysis Clause 14 requires before you transfer. Both parties warrant that they have no reason to believe the destination's laws and practices, including rules on government access to data, prevent the importer from meeting the clauses. To give that warranty, Clause 14(b) requires you to take account of:
- the specific circumstances of the transfer: the processing chain, the parties, the purpose, the categories and format of the data, the sector and where the data is stored;
- the laws and practices of the destination relevant to those circumstances, and their limits and safeguards;
- any contractual, technical or organisational safeguards you add, such as encryption where the importer does not hold the keys.
Clause 14(d) requires the assessment to be documented and made available to the supervisory authority on request. The EDPB's Recommendations 01/2020 (final version adopted 18 June 2021) set out the method in six steps: know your transfers; identify the transfer tool; assess whether it is effective given the destination's law and practice; adopt supplementary measures where it is not; take any procedural steps; and re-evaluate at appropriate intervals. If the assessment shows the data cannot be adequately protected, Clause 14(f) requires you to suspend the transfer.
In practice a TIA is a short structured document per vendor or per transfer type. The vendors that matter most are your critical tier: the ones that hold production data. See our vendor risk management guide for how to tier them.
The EU-US Data Privacy Framework in October 2026
The Commission adopted its adequacy decision for the EU-US Data Privacy Framework (DPF) on 10 July 2023. A transfer to a US company that has self-certified to the DPF and covers the data you send needs no SCCs or TIA. Transfers to US companies outside the DPF still need SCCs and a TIA. You can check a company's status on the public DPF list, and certifications must be renewed every year.
The framework is in force but contested. On 3 September 2025 the EU General Court dismissed the first challenge to it (Latombe v Commission, T-553/23). In June 2026 the US Supreme Court, in Trump v. Slaughter, held that statutory protections against the President removing Federal Trade Commission members were unconstitutional; the FTC is one of the DPF's enforcement bodies. The privacy group noyb then asked the Commission to repeal the decision and said it would bring an annulment action. Until a court annuls it or the Commission withdraws it, the adequacy decision stands. The two previous EU-US arrangements were both struck down by the Court of Justice, so many companies keep SCCs in their US contracts as a fallback that takes effect if the DPF falls.
UK transfers: the IDTA and the Addendum
The UK left the EU SCC system with Brexit. Under the UK GDPR, a restricted transfer needs UK adequacy regulations, an appropriate safeguard, or an exception. The ICO issued two sets of standard clauses, both laid before Parliament on 2 February 2022: the International Data Transfer Agreement (IDTA), and the International Data Transfer Addendum, which makes the EU SCCs work for UK transfers.
| Tool | What it is | When to use it |
|---|---|---|
| IDTA | The ICO's International Data Transfer Agreement: four parts, with tables you complete and mandatory clauses | UK-only transfers, or where you want a standalone UK contract |
| Addendum | The ICO's International Data Transfer Addendum to the EU SCCs | You already use the EU SCCs and want one contract for EU and UK transfers |
| UK Extension (data bridge) | UK adequacy regulations for US businesses certified to the UK Extension of the DPF | The US importer is on the DPF list with an active UK Extension certification |
| Transfer risk assessment | The UK's version of a TIA, now called the data protection test: the protection must not be materially lower after transfer | Before relying on the IDTA, the Addendum or another safeguard |
The EU SCCs alone are not valid for UK restricted transfers. Use the Addendum with them, or the IDTA.
The Data (Use and Access) Act 2025 reworded the UK test: a safeguard can be relied on only if the protection is not materially lower after the transfer, judged reasonably and proportionately. The ICO says this does not materially change how transfers work, plans to update the IDTA and Addendum during 2026, and tells organisations to keep using the current versions; both can be set to update automatically when it does. For transfers in the other direction, the European Commission renewed the UK's EU adequacy decisions on 19 December 2025, and they last until 27 December 2031. The UK Extension for US transfers is the UK's own regulation and, as the ICO clarified in July 2026, is independent of the EU's finding on the US.
How TryTrustable tracks transfers
Most transfer failures are paperwork failures: a vendor added without a DPA, a sub-processor in a new country, a contract that expired. The platform keeps the register that catches them.
| In TryTrustable | What it does |
|---|---|
| Vendor register | Each vendor's tier, the data it touches, and whether a signed DPA is on file |
| Processor register | Contract reference and validity for each processor, and its country checked against destinations you have restricted |
| Controls | Transfer controls mapped across GDPR, UK GDPR and your other frameworks, with the evidence kept in one ledger |
We record and check your transfer paperwork. We do not draft SCCs or carry out TIAs.
The things people ask us
Are standard contractual clauses still valid in 2026?
Yes. The 2021 SCCs adopted in Decision (EU) 2021/914 remain valid and are the most used transfer tool. The older 2001 and 2010 clauses stopped providing safeguards after 27 December 2022.
Which SCC module do I need?
Match the roles: Module One for controller to controller, Two for controller to processor, Three for processor to sub-processor, Four for processor back to controller. Most SaaS vendor contracts use Module Two.
Do I need a transfer impact assessment if I sign SCCs?
Yes. Clause 14 requires both parties to assess the destination's laws and practices, document it and make it available to the supervisory authority on request.
Do I need SCCs for a US vendor certified to the Data Privacy Framework?
Not while the adequacy decision stands, if the vendor's certification is active and covers the data. Many companies still include SCCs as a fallback in case the framework is annulled.
Can I use the EU SCCs for UK transfers?
Not on their own. Add the ICO's International Data Transfer Addendum, or use the IDTA instead, and complete a transfer risk assessment.
What is the difference between a TIA and a DPIA?
A transfer impact assessment looks at whether a destination country's law lets the importer protect the data. A DPIA looks at the risk of a processing activity to people's rights. A risky transfer can need both.
Does TryTrustable draft SCCs or run TIAs?
No. The platform records which vendors and processors you use, where they are, and whether the contracts are on file and valid. Drafting and assessing stay with you and your counsel.
Know where your vendors are, and what the paperwork says.
Thirty minutes on your vendor list, your transfer contracts and the GDPR and UK GDPR controls behind them.